Stenographer is a full-packet-capture utility designed for buffering packets to disk for intrusion detection and incident response purposes. It offers high-performance NIC-to-disk packet writing, efficient disk management to handle file deletion as disk space fills up, and easy retrieval of specific packet sets. It excels in quickly writing packets to disk at speeds of around 10Gbps on multi-core, multi-disk systems, managing disk usage to store longer durations during traffic lulls, and deleting the oldest packets when reaching disk limits. However, it is not suitable for complex packet processing like TCP stream reassembly, as its focus on speed sacrifices such functionalities. Additionally, reading back large amounts of packets (>1% of packets written) can lead to disk read and write competition issues.
FEATURES
SIMILAR TOOLS
Tcpdump is a command-line packet analyzer for capturing and analyzing network traffic.
A multi-threading tool for sniffing HTTP header records with support for offline and live sniffing, TCP flow statistics, and JSON output.
JARM is a TLS server fingerprinting tool used for identifying server configurations and malicious infrastructure.
A website scanner that provides a sandbox for the web, allowing users to scan URLs and websites for potential threats and vulnerabilities.
A command-line tool for taking screenshots of web pages using Chrome Headless
A network detection and response solution that uses AI and machine learning to monitor network traffic, identify malicious behavior, and connect related security events to reveal attack patterns without requiring endpoint agents.
Netis Cloud Probe is an open source project for capturing and analyzing network packets across different machines.
Repository of pcap traces for evaluating Network Intrusion Detection Systems in HVAC systems.
Azure DDoS Protection and Mitigation Services by Microsoft Azure for secure cloud solutions.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.